I don’t understand that. To me the severity has nothing to do with how popular is a code path, but whether that code path is accessible to an attacker. If I upload a specially crafted .mkv with a little known codec on YouTube and they use ffmpeg to process it, and I compromise YouTube’s infrastructure that way, it’s a pretty big deal, no matter the popularity of that codec.
I understand that from the perspective of "how many people will this crash for", but from a security perspective it is nonsensical. Even if it is an uncommon codec if the authors decide to keep the codepath there by default it is exploitable in most installs.
I love ffmpeg but that whole episode left a bit of a bad taste.
If you make a video player based on ffmpeg you take input videos. The attacker can share a specially crafted video with the victim. Same kind of attack as sharing word documents.
That's true for targeted attacks. For untargeted attacks, attackers have little incentive to do the exploit.